Enterprise-level zero-trust security hub and USB access security control method
Through the closed-loop hardware design of the enterprise-grade zero-trust security hub, front-end security control of USB devices is achieved, solving the problem that existing hubs are prone to data leakage and virus propagation, and providing an enterprise-grade security protection solution.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- GUIZHOU YIXI CLOUD TECHNOLOGY CO LTD
- Filing Date
- 2026-01-29
- Publication Date
- 2026-05-08
AI Technical Summary
Existing USB hubs lack device identification and front-end protection, which can easily lead to data leaks and virus propagation, failing to meet the security requirements of enterprise-level scenarios.
Design an enterprise-grade zero-trust security hub, including a USB expansion module, device detection module, type judgment module, and port switching module. Through hardware closed-loop linkage, it realizes the security control logic of "detect first, judge then, and connect later" to block high-risk USB devices from communicating with the host.
It completely eliminates the risk of illegal data extraction and virus transmission through USB devices, provides reliable USB access security, is suitable for enterprise-level scenarios, and does not affect the original system functions of the host or the performance of security devices.
Smart Images

Figure CN122001644A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of hub technology, and more particularly to an enterprise-level zero-trust security hub and a USB access security management method. Background Technology
[0002] In the information age, the demand for connecting various terminal devices to hosts is growing. The number of USB ports natively configured on motherboards and chassis is often insufficient to meet the needs of multiple devices being connected at the same time. Therefore, USB hubs have emerged. Their core function is to expand the number of USB ports on the host, solve the pain point of insufficient interface resources, and provide users with a more convenient device connection experience.
[0003] Currently, mainstream USB hubs represent a basic, first-generation hub solution, primarily targeting the consumer market. Their core design focuses solely on interface expansion, lacking the ability to identify and determine the type of USB devices connected. All connected devices are managed directly by the host operating system by default, without any pre-installed security mechanisms. However, as the nation increasingly emphasizes data asset security, data breaches and virus propagation risks have become significant hidden dangers in the digital transformation and smart city construction processes of various industries. The current design of USB hubs lacking security controls, coupled with reliance on software or system-level USB device interception methods, is outdated. These methods are not only easily cracked, but the cracking operations often leave no trace. For example, by inserting a bootable USB drive after the computer is powered off and booting the host with that device, illegal disk data can be extracted or viruses can be implanted. After the host restarts its original system, the virus can spread within the internal network, creating a significant security blind spot for internal information management and seriously threatening data security.
[0004] Therefore, there is an urgent need for a USB hub with security management capabilities to solve the problems of existing hubs lacking device identification and front-end protection, which can easily lead to data leakage and virus propagation, and provide reliable USB access security for enterprise-level scenarios. Summary of the Invention
[0005] In view of this, this application provides an enterprise-level zero-trust security hub and USB access security management method to solve the problems of existing hubs lacking device identification and front-end protection, which can easily lead to data leakage and virus propagation, and provide reliable USB access security for enterprise-level scenarios.
[0006] Specifically, this application is implemented through the following technical solution:
[0007] The first aspect of this application provides an enterprise-grade zero-trust security hub, which includes a USB expansion module, a device detection module, a type determination module, and a port switching module; wherein...
[0008] The USB expansion module is used to expand the host's USB downstream port for external USB devices to access, and the upstream end of the USB expansion module is connected to the port switching module.
[0009] The device detection module is connected to the USB expansion module and is used to capture the access signal of the external USB device and process the access signal;
[0010] The type determination module is connected to the device detection module and is used to receive the processed access signal and identify the type of all connected external USB devices.
[0011] The port switching module is connected to the type judgment module and the host USB interface respectively, and is used to control the connection and disconnection between the USB expansion module and the host USB interface according to the recognition result of the type judgment module, so as to perform security management.
[0012] A second aspect of this application provides an enterprise-level zero-trust USB access security management method, the method being applied to any of the enterprise-level zero-trust security hubs provided in the first aspect of this application; the method includes:
[0013] The device detection module captures the access signal of the external device on the USB downstream port in real time, processes the access signal, and then transmits it to the type determination module.
[0014] The type determination module receives the processed access signal, identifies the type of all connected external USB devices, and determines whether there is a storage or communication USB device.
[0015] The port switching module controls the connection / disconnection status between the USB expansion module and the host USB interface based on the identification result of the type judgment module.
[0016] The enterprise-level zero-trust security hub and USB access security management method provided in this application, through the setting of an external intelligent enterprise-level zero-trust security hub composed of a USB expansion module, a device detection module, a type judgment module, and a port switching module, utilizes a hardware closed-loop linkage of "USB expansion module expanding ports for device access, device detection module capturing and processing access signals, type judgment module identifying device type, and port switching module controlling access based on the identification result." This constructs a front-end security fortress, realizing a zero-trust management logic of "detect first, judge then, connect later," physically blocking direct communication between high-risk USB devices such as storage and communication devices and the host, completely eliminating the possibility of booting from a USB flash drive. The risk of unauthorized data extraction, virus implantation, and virus spread within internal networks is virtually eliminated by this hub, reducing the possibility of data leakage and virus transmission via USB ports to almost zero. Furthermore, this hub employs an independent hardware architecture design, independent of host BIOS settings, operating systems, and any driver software, and is not limited by motherboard manufacturers, CPU models, or other core components. While achieving robust security protection, it does not affect the normal function of the original host system or alter the original performance of security-type USB devices. It can be adapted for use without modifying existing terminal hardware and systems, becoming an upgraded and enhanced solution for information and data security in enterprise-level scenarios, providing reliable USB access security for digital transformation and smart construction across various industries. Attached Figure Description
[0017] Figure 1 This is a schematic diagram of the structure of an enterprise-level zero-trust security hub provided in Embodiment 1 of this application;
[0018] Figure 2 A flowchart of the enterprise-level zero-trust USB access security management method provided in Embodiment 2 of this application. Detailed Implementation
[0019] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application.
[0020] The terminology used in this application is for the purpose of describing particular embodiments only and is not intended to be limiting of the application. The singular forms “a,” “the,” and “the” used herein are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used herein refers to and includes any and all possible combinations of one or more of the associated listed items.
[0021] It should be understood that although the terms first, second, third, etc., may be used in this application to describe various information, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from one another. For example, without departing from the scope of this application, first information may also be referred to as second information, and similarly, second information may also be referred to as first information. Depending on the context, the word "if" as used herein may be interpreted as "when," "when," or "in response to determination."
[0022] The following specific embodiments are given to illustrate the technical solution of this application in detail.
[0023] Figure 1 This is a schematic diagram of the enterprise-level zero-trust security hub provided in Embodiment 1 of this application. Please refer to... Figure 1 The enterprise-grade zero-trust security hub provided in this embodiment includes a USB expansion module, a device detection module, a type determination module, and a port switching module; wherein,
[0024] The USB expansion module is used to expand the host's USB downstream port for external USB devices to access, and the upstream end of the USB expansion module is connected to the port switching module.
[0025] The device detection module is connected to the USB expansion module and is used to capture the access signal of the external USB device and process the access signal;
[0026] The type determination module is connected to the device detection module and is used to receive the processed access signal and identify the type of all connected external USB devices.
[0027] The port switching module is connected to the type judgment module and the host USB interface respectively, and is used to control the connection and disconnection between the USB expansion module and the host USB interface according to the recognition result of the type judgment module, so as to perform security management.
[0028] Specifically, an enterprise-grade zero-trust security hub is a hardware device used to expand the host's USB ports while providing front-end security protection capabilities. Its core function is to enable secure management and control of external USB devices based on the expanded USB connection ports. The enterprise-grade zero-trust security hub consists of four parts: a USB expansion module, a device detection module, a type determination module, and a port switching module. The upstream end of the USB expansion module is connected to the port switching module, the device detection module interfaces with the USB expansion module, the type determination module is connected to the device detection module, and the port switching module is also connected to both the type determination module and the host's USB ports.
[0029] Furthermore, the USB expansion module is responsible for expanding more USB downstream ports for external devices to access; the device detection module is used to capture device access signals and process them into recognizable signals; the type judgment module is responsible for identifying the type of accessing device (such as whether it is a high-risk storage / communication device); and the port switching module controls the connection between the expansion module and the host based on the identification results.
[0030] In practice, when an external USB device is connected to the downstream port of the USB expansion module, the device detection module immediately captures the connection signal and processes it into a signal recognizable by the type judgment module. Upon receiving the signal, the type judgment module performs type identification on all connected devices. If a high-risk device is identified, the port switching module disconnects the USB expansion module from the host's USB interface, preventing communication between the device and the host. If all devices are secure, the port switching module reconnects, allowing the device to interact normally with the host. Through this hardware closed-loop linkage, a pre-emptive security control mechanism of "detect first, judge then, connect later" is achieved, physically blocking security threats from high-risk devices.
[0031] Optionally, the enterprise-grade zero-trust security hub adopts a fixed structure design, which does not retain the original USB interface of the host, but only retains a dedicated interface that is compatible with the USB expansion module. The dedicated interface is fixed by physical snap-fit or welding, and can be released under physical action.
[0032] Specifically, the design employs a fixed structure and retains only a dedicated interface for compatibility with USB expansion modules. It is fixed by physical clips or welding. The core purpose is to build a solid last line of defense for security from a physical perspective, eliminating the vulnerabilities of existing technologies where "software interception is easily cracked and hardware modifications leave no trace." On the one hand, eliminating the original USB interface on the host completely prevents users from bypassing the security hub and directly connecting high-risk USB devices through the native interface. This ensures that all external USB device connections must go through a secure "detection-judgment-control" process, leaving no blind spots in access control. On the other hand, the physical snap-fit or soldering method gives the dedicated interface strong anti-tampering capabilities. To illegally modify the interface to bypass security control, physical damage is required to remove the fixation. This physical damage leaves obvious traces, facilitating traceability and verification by management departments, solving the problem of no trace after traditional software protection is cracked. At the same time, this design complements the hub's independent hardware security control logic. Through the dual protection of "physical structure restrictions + hardware closed-loop control," the absoluteness of security protection is further strengthened, ensuring the insurmountability of USB access security control in enterprise-level scenarios and providing more thorough protection for data asset security.
[0033] The modules will be introduced in turn.
[0034] Specifically, the USB expansion module is used to expand the host's USB downstream port for external USB devices to access, and the upstream end of the USB expansion module is connected to the port switching module.
[0035] Optionally, the USB expansion module includes at least two USB 3.0 hub chips, which cooperate to expand and form at least seven USB downstream ports, and all USB downstream ports are connected to the corresponding device detection module.
[0036] Specifically, in the USB expansion module of the enterprise-level zero-trust security hub in this embodiment, the uplink refers to the interface end where the USB expansion module establishes a connection with the upstream device (here, the port switching module). Its core function is to realize signal transmission between the USB expansion module and the port switching module, and it is the "channel entry" for data interaction between the USB expansion module and other core modules of the hub (such as the type judgment module and the host interface). The downlink refers to the interface end of the USB expansion module facing external USB devices, which is used to provide an expanded access port for external USB devices such as mice, USB flash drives, and external hard drives to be directly plugged in. It is the "channel exit" for external devices to establish a connection with the hub.
[0037] Furthermore, the USB 3.0 hub chip serves to expand the USB interface and distribute signals. On one hand, through the design of at least two chips working together, it can overcome the port limit of a single chip, stably expanding to at least seven USB downstream ports to meet the needs of multiple external devices accessing simultaneously, solving the core pain point of insufficient native USB interfaces on the host. On the other hand, as the core functional carrier of the USB expansion module, it not only undertakes the task of port expansion but also synchronously transmits access signals to the device detection module when an external device accesses the downstream port, providing triggering conditions for the subsequent "detection-judgment-control" security process. At the same time, the choice of the USB 3.0 specification ensures the data transmission rate, ensuring that security control does not affect the normal performance of the device. All expanded downstream ports are connected to the corresponding device detection module, realizing accurate detection and control of each accessed device.
[0038] In practice, at least two USB 3.0 hub chips are selected as the core components of the USB expansion module. The two USB 3.0 hub chips are configured to work together, and at least seven USB downstream ports are formed through signal coordination and port expansion logic between the chips. The upstream end of the USB expansion module is physically connected to the port switching module to realize signal transmission between the two. At the same time, each USB downstream port formed by expansion is connected to the device detection module one by one to ensure that when an external USB device is connected to each downstream port, the relevant signals can be accurately transmitted to the device detection module.
[0039] Specifically, the device detection module is connected to the USB expansion module and is used to capture the access signal of the external USB device and process the access signal.
[0040] Optionally, the device detection module includes a USB hub chip and a signal processing circuit. The USB hub chip corresponds one-to-one with the downlink port of the USB expansion module. When an external USB device is connected, the corresponding pin of the USB hub chip outputs a PWM signal. The signal processing circuit converts and processes the PWM signal and outputs a level signal to the type judgment module.
[0041] Optionally, the signal processing circuit is an integrator circuit with seven independent branches. Each independent branch corresponds to a USB downstream port of the USB expansion module. Each independent branch includes a resistor, a capacitor, and a switching transistor, and is used to independently process the PWM signal of the corresponding port.
[0042] Specifically, the USB hub chip is the core component of the device detection module. It is a dedicated chip configured one-to-one with each downstream port of the USB expansion module to sense the device connection status of the corresponding port. When an external USB device is connected to the corresponding downstream port of the USB expansion module, the corresponding pin of the chip will synchronously output a PWM signal, converting the physical state of "device connection" into an electrical signal that can be recognized by subsequent circuits, providing the original trigger signal for subsequent signal processing and type determination.
[0043] The signal processing circuit is a dedicated circuit in the device detection module used to process the output signals of the USB hub chip. In this embodiment, it is specifically an integrator circuit, containing seven independent branches (corresponding one-to-one with the seven downstream ports of the USB expansion module). Each branch consists of resistors, capacitors, and switching transistors. The signal processing circuit receives the PWM signal output by the USB hub chip and, through the coordinated operation of the resistors, capacitors, and switching transistors within the circuit, converts the PWM signal into a level signal that the type determination module can directly recognize, and then transmits this level signal to the type determination module.
[0044] It should be noted that, firstly, this application considers that the seven independent branches of the integrating circuit can correspond one-to-one with the seven downstream ports of the USB expansion module, enabling independent processing of the input signal of each port and avoiding interference from multiple port signals; secondly, considering that the PWM signal output by the USB hub chip is a pulse modulation signal, which cannot be directly recognized by the type judgment module, the integrating circuit can stably convert the pulse signal into a stable level signal, meeting the signal input requirements of the type judgment module; furthermore, the integrating circuit, composed of resistors, capacitors, and switching transistors, has a simple structure and high reliability, and can quickly respond to signal processing needs in a hardware closed loop without relying on software assistance, which fits the design logic of independent hardware protection for the hub.
[0045] PWM signal, or Pulse Width Modulation signal, is a periodic pulse electrical signal that transmits information by changing the pulse width. In this embodiment, it is output by the USB hub chip when a device is connected, indicating that "an external USB device is connected to the corresponding downstream port." Level signal is an electrical signal with clearly defined high and low potential states (usually divided into high and low levels). In this embodiment, it is generated by an integrating circuit after processing the PWM signal. It is a digital signal that the type determination module can directly recognize, used to convey explicit information to the type determination module about whether a device is connected to the corresponding port.
[0046] In practice, the USB hub chip in the device detection module is wired one-to-one with each downlink port of the USB expansion module to ensure that the access status of each downlink port can be sensed by the corresponding USB hub chip in real time. At the same time, an integrator circuit consisting of 7 independent branches is built as a signal processing circuit. Each independent branch is designed with resistors, capacitors and switching transistors soldered according to the preset circuit design. Each independent branch is then electrically connected to a downlink port of the USB expansion module to form a one-to-one signal transmission path of "one downlink port - one corresponding pin of the USB hub chip - one independent branch of the integrator circuit". When an external USB device is plugged into a downstream port of the USB expansion module, the corresponding USB hub chip senses the change in the physical state of the device connection through its internal circuitry. It then outputs a PWM signal (Pulse Width Modulation) representing this connection state on its preset corresponding pin. This PWM signal is transmitted through a pre-built electrical path to the corresponding independent branch in the integrator circuit. Inside this branch, resistors limit current and divide voltage, capacitors store and discharge charge, and switching transistors work together to regulate the signal transmission state. These three components filter and integrate the PWM signal according to the working principle of the integrator circuit, converting the periodic pulse signal into a stable, continuous high and low level signal. The processed signal is then accurately transmitted to the corresponding signal receiver of the type determination module through a preset signal transmission line, completing the entire process of capturing and processing the connection signal.
[0047] Specifically, the type determination module is connected to the device detection module and is used to receive the processed access signal and identify the type of all connected external USB devices.
[0048] Optionally, the type determination module is an ARM SOC chip. The ARM SOC chip is connected to the device detection module through an IO interface to receive level signals and parse the type of the access device based on the USB device protocol to identify whether it is a storage device or a communication device.
[0049] Optionally, when the type determination module detects the presence of a storage or communication USB device, it sends a disconnect control signal to the port switching module, which then disconnects the USB expansion module from the host USB interface while maintaining its connection with the type determination module. When the type determination module detects the absence of storage or communication USB devices, it sends a conduction control signal, which then connects the USB expansion module to the host USB interface.
[0050] Specifically, an ARM SOC chip, or System on Chip, is an integrated circuit that integrates a central processing unit, memory, interface circuits, peripheral control, and other functional modules onto a single chip. The USB device protocol is a standardized set of communication rules and specifications for data interaction and identification between USB (Universal Serial Bus) devices and hosts / hubs. It includes core elements such as device type encoding, data transmission formats, and command interaction logic. The USB device protocol provides a unified basis for device type identification. When different types of USB devices (such as storage devices, keyboards / mice, and audio devices) are connected, they send their type identification information to the connected hub / host through this protocol. The ARM SOC chip can accurately determine the specific type of the connected device by parsing this standardized information.
[0051] It should be noted that the reason this application controls the connection between the USB expansion module and the host USB interface based on the type of access device is to implement precise control over the different security risks of different types of USB devices: storage devices (such as USB flash drives and external hard drives) can directly store and read host data, while communication devices have data transmission capabilities. Both pose a high security risk of illegally extracting host data and implanting viruses, making them the main carriers of data leaks and the spread of viruses within internal networks. On the other hand, non-storage / non-communication USB devices such as keyboards, mice, and printers only have specific functional interaction capabilities and no risk of data storage or active transmission, thus posing no threat to host data security. By using an ARM SOC chip to parse the device type based on the USB device protocol and then controlling the connection of the port switching module, differentiated control of "blocking high-risk devices and allowing safe devices" can be achieved. This not only cuts off the security risks brought by storage and communication devices at the source but also does not affect the use of normally functional devices, meeting the dual needs of enterprise-level scenarios for USB access security and ease of use.
[0052] In practical implementation, the core component of the type determination module, the ARM SOC chip, is electrically connected one-to-one with the signal output terminal of the device detection module through its I / O interface, establishing a stable signal transmission path. This ensures that the level signal corresponding to each downlink port processed by the device detection module can be accurately transmitted to the corresponding signal receiving pin of the ARM SOC chip. The ARM SOC chip is pre-programmed with a built-in USB device protocol parsing logic, which includes a USB device type encoding lookup table, protocol instruction parsing algorithm, and device type determination rules. When the ARM SOC chip receives a level signal through the I / O interface, it determines that an external device is connected to the downlink port of the corresponding USB expansion module and then initiates the device type identification process. The ARM SOC chip establishes communication interaction with the connected device based on the USB device protocol, sends a device type query command, receives response data containing its own type identifier from the connected device, and then decodes and matches the response data through its built-in parsing program. By referring to the USB device type encoding lookup table, it accurately determines whether the device is a storage device or a communication device. If, during the identification process, the ARM SOC chip detects that the type identifier of any access device matches the code of a storage or communication device, it immediately sends a high-level (or preset waveform) disconnect control signal to the port switching module through a preset control signal output pin. Upon receiving this disconnect control signal, the port switching module activates its internal switching element, cutting off the signal and data transmission path between the upstream end of the USB expansion module and the host USB interface, while maintaining the control signal connection between itself and the ARM SOC chip to continuously receive subsequent control commands. If, after completing the type identification of all access devices, the ARM SOC chip does not detect any storage or communication device type identifiers (i.e., all devices are not high-risk types), it sends a low-level (or another preset waveform) conduction control signal to the port switching module through the control signal output pin. Upon receiving this conduction control signal, the port switching module switches its internal switching element, conducting the path between the upstream end of the USB expansion module and the host USB interface, enabling external devices to perform normal data interaction and functional collaboration with the host.
[0053] Optionally, when multiple external USB devices are connected to the USB expansion module at the same time, the type determination module performs unified type identification on all connected external USB devices based on the signal change triggered by the last connected external USB device.
[0054] Specifically, this application uses the signal change triggered by the last connected external USB device as a benchmark to perform unified type identification on all connected devices. The core purpose is to avoid identification conflicts and blind spots in control when multiple devices are connected concurrently. On the one hand, when multiple devices are connected at the same time, the signals triggered by each device may overlap, be delayed, or have a disordered order. If the devices are identified one by one according to the order of connection, some device signals may not be fully captured, and the identification results may be missed. However, by using the signal change of the last device as the unified trigger point, it can be ensured that all devices have been stably connected to the USB expansion module, and the type judgment module can perform a one-time identification. Obtaining complete information on all connected devices avoids incomplete identification due to asynchronous device access. On the other hand, in multi-device access scenarios, the overall access status only tends to stabilize after the last device is connected. Starting unified identification based on this can avoid repeatedly triggering the identification process, reduce the computational load of the type judgment module, and ensure that the identification results cover all connected devices. This prevents criminals from exploiting the vulnerability of "first connecting to a secure device to pass identification, and then subsequently connecting to a high-risk device to evade control," ensuring the comprehensiveness and rigor of security control, which aligns with the core design goal of "no dead angle protection" of enterprise-level zero-trust security hubs.
[0055] Specifically, the port switching module is connected to the type judgment module and the host USB interface respectively, and is used to control the connection and disconnection between the USB expansion module and the host USB interface according to the recognition result of the type judgment module, so as to perform security management.
[0056] Optionally, the port switching module is a USB 3.0 high-speed switch. The first end of the USB 3.0 high-speed switch is connected to the upstream end of the USB expansion module, the second end is connected to the communication interface of the type judgment module, and the third end is connected to the host USB interface. The connection object is switched by switching control signal.
[0057] Specifically, the USB 3.0 high-speed switch is a high-performance hardware switching element adapted to the USB 3.0 transmission protocol. It has high-speed data transmission capability and precise path switching control function. It integrates signal detection and switch driving circuits, which can realize fast and stable switching between different paths according to the input control signal. At the same time, it can meet the high-speed data transmission bandwidth requirements under the USB 3.0 protocol, ensuring the integrity and timeliness of data transmission.
[0058] In this embodiment, the USB 3.0 high-speed switch serves as the core carrier of the hub port switching module. Through precise connection and switching of its three ports, it achieves core security control actions. At the hardware connection level, the first terminal of the USB 3.0 high-speed switch connects to the upstream terminal of the USB expansion module, receiving external device signals transmitted by the expansion module; the second terminal connects to the communication interface of the type determination module, receiving on / off control signals sent by the ARM SOC chip; and the third terminal connects to the host USB interface, establishing a signal path with the host. At the functional execution level, the USB 3.0 high-speed switch achieves bidirectional switching of the path based on the control signals output by the type determination module.
[0059] In the specific implementation, a USB 3.0 high-speed switch is selected as the core hardware of the port switching module. The first pin of the switch is electrically soldered to the uplink terminal of the USB expansion module to establish a path for external device signals to be transmitted to the port switching module. The second pin of the switch is connected to the communication interface of the type judgment module (ARM SOC chip) to establish a data link and build a transmission channel for control signals. The third pin of the switch is hardware-interfaced with the signal input terminal of the host USB interface to build a data interaction path between the hub and the host. When the type identification module completes device type recognition and outputs a control signal, the control signal is transmitted to the control pin of the USB 3.0 high-speed switch via a preset communication link. After receiving the control signal, the internal drive circuit of the switch triggers the internal electronic switch element to operate. If the received control signal is a disconnect control signal, the switch element is driven to switch to the disconnect state, cutting off the signal path between the first end (USB expansion module uplink end) and the third end (host USB interface), while maintaining the connection between the second end and the control signal of the type identification module. If the received control signal is a conduction control signal, the switch element is driven to switch to the conduction state, connecting the signal path between the first end and the third end, enabling external devices on the USB expansion module to perform high-speed data interaction with the host based on the USB 3.0 protocol, thereby achieving secure management of external devices connected to the host.
[0060] The enterprise-grade zero-trust security hub provided in this embodiment, through the setting of an external intelligent enterprise-grade zero-trust security hub composed of a USB expansion module, a device detection module, a type judgment module, and a port switching module, utilizes a hardware closed-loop linkage of "USB expansion module to expand ports for device access, device detection module to capture and process access signals, type judgment module to identify device type, and port switching module to control on / off based on the identification results." On the one hand, it constructs a front-end security fortress, realizing the zero-trust control logic of "detect first, judge then, connect later," physically blocking direct communication between high-risk USB devices such as storage and communication devices and the host, and completely eliminating illegal access via bootable USB flash drives and other devices. The risks of data extraction, virus implantation, and virus spread within internal networks are virtually eliminated, reducing the possibility of data leakage and virus transmission via USB ports to almost zero. Furthermore, this hub employs an independent hardware architecture design, independent of host BIOS settings, operating systems, and any driver software. It is also not limited by motherboard manufacturers, CPU models, or other core components. While achieving robust security protection, it does not affect the normal function of the original host system or alter the original performance of security-type USB devices. It can be adapted for use without modifying existing terminal hardware and systems, becoming an upgraded and enhanced solution for information and data security in enterprise-level scenarios, providing reliable USB access security for digital transformation and smart construction across various industries.
[0061] Corresponding to the aforementioned embodiment of an enterprise-level zero-trust security hub, this application also provides an embodiment of an enterprise-level zero-trust USB access security management method.
[0062] Figure 2 This is a flowchart illustrating the enterprise-level zero-trust USB access security management method provided in Embodiment 2 of this application. Please refer to... Figure 2 The method provided in this embodiment is applied to any of the enterprise-level zero-trust security hubs described in the first aspect of this application; the method includes:
[0063] S201. The device detection module captures the access signal of the external device on the USB downlink port in real time, processes the access signal, and then transmits it to the type judgment module.
[0064] S202. The type determination module receives the processed access signal, performs type identification on all accessed external USB devices, and determines whether there is a storage or communication USB device.
[0065] S203 The port switching module controls the connection / disconnection status between the USB expansion module and the host USB interface based on the identification result of the type judgment module.
[0066] The method in this embodiment can be used to execute Figure 1The steps of the device embodiment shown are similar in principle and process, and will not be repeated here.
[0067] The specific implementation process of the functions and roles of each unit in the above device can be found in the implementation process of the corresponding steps in the above method, and will not be repeated here.
[0068] For the device embodiments, since they basically correspond to the method embodiments, the relevant parts can be referred to in the description of the method embodiments. The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this application according to actual needs. Those skilled in the art can understand and implement this without creative effort.
[0069] The above description is merely a preferred embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application.
Claims
1. An enterprise-grade zero-trust security hub, characterized in that, The enterprise-grade zero-trust security hub includes a USB expansion module, a device detection module, a type determination module, and a port switching module; wherein... The USB expansion module is used to expand the host's USB downstream port for external USB devices to access, and the upstream end of the USB expansion module is connected to the port switching module. The device detection module is connected to the USB expansion module and is used to capture the access signal of the external USB device and process the access signal; The type determination module is connected to the device detection module and is used to receive the processed access signal and identify the type of all connected external USB devices. The port switching module is connected to the type judgment module and the host USB interface respectively, and is used to control the connection and disconnection between the USB expansion module and the host USB interface according to the recognition result of the type judgment module, so as to perform security management.
2. The enterprise-grade zero-trust security hub according to claim 1, characterized in that, The USB expansion module includes at least two USB 3.0 hub chips, which cooperate to expand and form at least seven USB downstream ports, and all USB downstream ports are connected to the corresponding device detection module.
3. The enterprise-grade zero-trust security hub according to claim 1, characterized in that, The device detection module includes a USB hub chip and a signal processing circuit. The USB hub chip corresponds one-to-one with the downlink port of the USB expansion module. When an external USB device is connected, the corresponding pin of the USB hub chip outputs a PWM signal. The signal processing circuit converts and processes the PWM signal and outputs a level signal to the type judgment module.
4. The enterprise-grade zero-trust security hub according to claim 3, characterized in that, The signal processing circuit is an integrator circuit with seven independent branches. Each independent branch corresponds to a USB downstream port of the USB expansion module. Each independent branch includes a resistor, a capacitor, and a switching transistor, and is used to independently process the PWM signal of the corresponding port.
5. The enterprise-grade zero-trust security hub according to claim 1, characterized in that, The type determination module is an ARM SOC chip. The ARM SOC chip is connected to the device detection module through an IO interface to receive level signals and parse the type of the access device based on the USB device protocol to identify whether it is a storage device or a communication device.
6. The enterprise-grade zero-trust security hub according to claim 1, characterized in that, The port switching module is a USB 3.0 high-speed switch. The first end of the USB 3.0 high-speed switch is connected to the upstream end of the USB expansion module, the second end is connected to the communication interface of the type judgment module, and the third end is connected to the host USB interface. The connection object is switched by switching control signal.
7. The enterprise-grade zero-trust security hub according to claim 1, characterized in that, When multiple external USB devices are connected to the USB expansion module at the same time, the type determination module uses the signal change triggered by the last connected external USB device as a reference to perform unified type identification for all connected external USB devices.
8. The enterprise-grade zero-trust security hub according to claim 1, characterized in that, When the type determination module detects the presence of a storage or communication USB device, it sends a disconnect control signal to the port switching module. The port switching module then disconnects the USB expansion module from the host USB interface while maintaining its connection with the type determination module. When the type determination module detects the absence of a storage or communication USB device, it sends a conduction control signal, and the port switching module then connects the USB expansion module to the host USB interface.
9. The enterprise-grade zero-trust security hub according to claim 1, characterized in that, The enterprise-grade zero-trust security hub adopts a fixed structure design, which does not retain the original USB interface of the host, but only retains a dedicated interface that is compatible with the USB expansion module. The dedicated interface is fixed by physical snap-fit or welding, and can be released under physical action.
10. An enterprise-level zero-trust USB access security management method, characterized in that, The method is applied to the enterprise-grade zero-trust security hub as described in any one of claims 1-9; The method includes: The device detection module captures the access signal of the external device on the USB downstream port in real time, processes the access signal, and then transmits it to the type determination module. The type determination module receives the processed access signal, identifies the type of all connected external USB devices, and determines whether there is a storage or communication USB device. The port switching module controls the connection / disconnection status between the USB expansion module and the host USB interface based on the identification result of the type judgment module.